upgrade to the latest version (0.1.2.16 or
0.2.0.4-alpha) to avoid this type of attack.
READ THREAD: http://minilien.com/?3Y4uiMXyun
Roger Dingledine wrote:
Tor 0.1.2.16 fixes a critical security vulnerability that allows a
remote attacker in certain situations to rewrite the user's torrc
configuration file. This can completely compromise anonymity of users
in most configurations, including those running the Vidalia bundles,
TorK, etc. Or worse.
......
(Typing on defcon network so will be quite brief)
The short answer is yes, this is an attack, and no, we're not going
to tell you exactly how it works yet. That's because several hundred
thousand people are vulnerable, and we're going to give them several
weeks to upgrade before we arm random people on the Internet with the
ability to launch this attack against them.
You should be one of the people who upgrades. :)
--Roger
READ THREAD: http://minilien.com/?3Y4uiMXyun


|